Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
ID: 560b9a6f-d0d4-5f7d-b7cd-bd679d81482b
STIX ID: report--560b9a6f-d0d4-5f7d-b7cd-bd679d81482b
Feed Name: The Hacker News
Cisco Talos analyzed msaRAT, a Rust implant deployed prior to Chaos ransomware encryption that spawns a headless Chrome/Edge, uses the Chrome DevTools Protocol to inject JavaScript, and tunnels encrypted C2 over a WebRTC data channel relayed via a Cloudflare Worker and Twilio TURN. The implant is delivered via an MSI masquerading as a Windows update, loads a DLL into memory, and executes commands received through the browser-driven channel; Talos published two network indicators but no file hashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
